Remote Code Execution by Subscriber+ users via WordPress shortcode
CVE-2022-24663
9.9CRITICAL
What is CVE-2022-24663?
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.
Affected Version(s)
PHP Everywhere WordPress 2.0.3